Improper control of a resource through its lifetime in Linux kernel - CVE-2026-97615
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to corrupt list state on another bridge.
The vulnerability exists due to reuse of a global frame-type handler list node in the Linux bridge CFM and MRP frame handlers when enabling a protocol on multiple bridges and unregistering it on one bridge. A local privileged user can create protocol instances on multiple bridges and remove an instance from one bridge to corrupt list state on another bridge.